XRP Ledger Patches Decade-Old Flaw That Could Create Spendable XRP
0
0

XRP Ledger developers have disclosed a critical vulnerability that could have allowed an attacker to create spendable XRP from nothing, bypassing safeguards designed to prevent the cryptocurrency’s supply from increasing.
The payment engine vulnerability was reported through the XRPL Bug Bounty program on September 22 by Cayden Liao and Veria AI. RippleX engineers reproduced the exploit on a standalone server, confirmed that the newly created XRP could be spent in a subsequent payment and raised its severity from major to critical.
There is no evidence the vulnerability was exploited on any public XRP Ledger network. Developers privately prepared a fix and released xrpld version 3.4.1 on September 25, two days after the patch was merged into the emergency release branch.
Integer Overflow Could Bypass XRP Supply Checks
The flaw existed in the XRP Ledger payment engine since approximately 2015 and involved unchecked 64-bit integer arithmetic when a payment consumed multiple offers from the network’s order book.
An attacker could create hundreds of accounts and place specially constructed offers selling small amounts of another token for extremely large amounts of XRP. A single payment consuming those offers could push the calculated total beyond the maximum value supported by the integer.
Instead of rejecting the transaction, the total would wrap around to a small number. Each offer owner could still receive the full XRP amount specified in its offer, while the buyer would be charged only the much smaller wrapped value.
The attack required only a few hundred XRP for account and offer reserves, much of which could later be recovered, plus ordinary transaction fees.
XRPL’s built-in check designed to ensure that transactions cannot create XRP would not have stopped the exploit. The invariant used the same type of arithmetic and could overflow in the same way, while a separate per-account balance limit could be bypassed by distributing the newly created XRP across hundreds of accounts.
The flaw was limited to deliberately constructed transactions and could not be triggered by normal payments or trading activity.
Validators Moved to 3.4.1 Within Hours
Developers chose to deploy the XRP overflow fix immediately rather than put it through XRPL’s normal amendment process, which generally requires more than 80% validator support for two weeks before a protocol change activates.
Leaving the vulnerability exposed throughout that period would have created a window in which the attack method was publicly known but still usable. More than 80% of validators on the default Unique Node List had upgraded to 3.4.1 on September 25, the same day the emergency version was released.
Version 3.4.1 now rejects payments when the offer total would overflow and uses a wider counter for the XRP-creation invariant. Additional balance calculations were also hardened against similar arithmetic failures.
The incident follows an unrelated xrpl.js supply-chain compromise discovered in 2025, which affected malicious JavaScript package releases rather than the XRP Ledger protocol itself.
XRPL’s amendment system is also being used for newer functionality such as the proposed XRPL Lending Protocol, where validator approval determines whether new transaction behavior becomes active.
The overflow flaw did not alter XRP’s existing supply. No unauthorized XRP has been identified, and server operators must now run xrpld 3.4.1 or newer to remain synchronized with the network.
The post XRP Ledger Patches Decade-Old Flaw That Could Create Spendable XRP appeared first on Crypto Adventure.
0
0
Securely connect the portfolio you’re using to start.





